Re: [PATCH] Protection for exploiting null dereference using mmap

From: Jan Engelhardt
Date: Thu Jun 07 2007 - 12:58:50 EST



On Jun 6 2007 08:47, Stephen Smalley wrote:
>
>I'd be ok with having a different default for SELinux vs. non-SELinux,
>i.e. no restrictions by default under dummy/capability, but restrict it
>by default to 64k if selinux is enabled. Then we can use policy to
>grant it as needed to the specific programs.

640k?



Jan
--
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/